Executive brief
Jupyter Notebook is a popular web-based interactive computing environment used by data scientists and developers. An attacker can inject malicious scripts by creating directories with crafted names that are improperly handled by the notebook interface, allowing them to steal session tokens or perform actions on behalf of users viewing the notebook.
Technical details
A cross-site scripting (XSS) vulnerability exists in Jupyter Notebook versions before 5.7.2 in the notebook/static/tree/js/notebooklist.js file, which handles directory URLs unsafely. The vulnerable code fails to properly sanitize or escape user-controlled input (directory names) before inserting them into the DOM. An attacker can craft a directory name containing JavaScript payloads that will be executed in the browser of any user accessing the notebook. The attack requires user interaction (victim must access the crafted directory via a link or navigate to it), but can affect multiple users on the same notebook server. The vulnerability was patched in version 5.7.2.
Affected products
- Project Jupyter Notebook before 5.7.2
Timeline
- 2018-11-21: disclosed
- 2018-11-21: patched: Patched in version 5.7.2